LWA-2026-5849 confirmed malware
paypal-postman-lib@1.0.2
Malicious code in paypal-postman-lib (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
combosquat namespace-reservation publish: the package name impersonates "PayPal Postman" (a legitimate API-client tool) by appending "-lib". The tarball contains only a package.json file (274 bytes) with no executable code, and declares a circular self-dependency on itself (paypal-postman-lib@^1.0.1). The package name is associated with previously flagged malware. The publisher staked the name but shipped no code — a typical namespace-grab pattern before delivering malicious payloads in a later version.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 09:12 PM
- analyzed
- Jun 22, 2026, 09:12 PM
Related advisories
- web3-token-helper@1.1.3
- zod-pino@1.0.122
- shadxino@1.0.7
- search-from-search@999.99.99
- @dilxzphrine/baileys@1.0.0
- node-core-libs@1.0.0
- tailwindcss-effector@1.7.0
- crosswalker@18.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.